> For the complete documentation index, see [llms.txt](https://docs.enzoic.com/enzoic-for-active-directory/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.enzoic.com/enzoic-for-active-directory/product-usage/logging-and-siem-integration/crowdstrike-falcon-integration.md).

# CrowdStrike Falcon Integration

Enzoic for Active Directory audit events can be pushed directly to your Crowdstrike Falcon instance. This allows you to leverage the rich search capabilities built into Falcon.

### 2.1 Falcon Configuration

1. From the hamburger menu at the top left, click *Next-Gen SIEM*, then in the flyout, click *Data onboarding*<br>

   <figure><img src="/files/dJ4ODdpp1qYPsmU9R0TR" alt=""><figcaption></figcaption></figure>
2. Click the *Data sources* tab.&#x20;
3. Click *Search by name*, and enter “http” (without quotes).<br>

   <figure><img src="/files/lW31WTekaJCyOgL01thk" alt=""><figcaption></figcaption></figure>
4. Click on the HEC / HTTP Event data source.
5. Enter the required information to setup the data source as follows
   1. For *Data source*, enter enzoic-for-ad-audit-log-data-source
   2. Select JSON as the *Data type*
   3. For *Connector name*, enter enzoic-for-ad-audit-log-connector
   4. In the *Parsers* drop down, search for and select the ***enzoic-enzoicforactivedirectory*** parser.
   5. Tick the affirmation checkbox at the bottom, above the Cancel button.
   6. Click *Save*<br>

      <figure><img src="/files/qIDqsRW2VVq52CQw5LAg" alt="" width="342"><figcaption></figcaption></figure>
6. Click *Close* on the modal popup.
7. Towards the top right of the page, click the *Generate API Key* button.

   <figure><img src="/files/kxkMP4er3i0IXDo5r7Lq" alt=""><figcaption></figcaption></figure>
8. On the Connection setup modal popup, copy off the API key and API URL values to a save and secure location. You will also need these to configure Enzoic for Active Directory in the next steps.

   <figure><img src="/files/0JR2egsB0NVdbOesDP7F" alt=""><figcaption></figcaption></figure>
9. In the Enzoic for Active Directory console, click Settings in the left navigation panel, then click on the Crowdstrike tab page.<br>

   1. Enter the API URL and API Key generated by Falcon, tick the Enabled checkbox, then click Update Configuration.

   <figure><img src="/files/Fac2w9mQ6ycLHJfY6KLl" alt=""><figcaption></figcaption></figure>

Enzoic for Active Directory is now setup to push all audit events to your Falcon instance.
